agentsclimarketplace

Shelves Security

Vulnerability scanning

769 rows from 206 repositories

Automated checks for known-bad patterns and known-bad versions.

What Vulnerability scanning skills agree on

209 skill files read, by 223 of the 238 authors on this shelf whose files we hold, 2026-09-06

The middle one of the 31 measured here is ~1.7k tokens long, counted with cl100k_base

Counted by distinct author, so one author publishing three of these counts once. Where a claim sits in fewer files than authors, that is said: a claim held by forty authors across three files is one file people copied, not forty people who agreed. Near-identical wordings are grouped and the other wordings are shown, so the grouping is yours to check.

What they tell the agent to do

  1. Fix critical findings immediately21 of 223 in 14 filesalso worded as Fix Critical and High findings; Address critical and high findings immediately
  2. Fix high findings before production18 of 223 in 12 filesalso worded as Fix Critical and High findings before release; fix high-risk findings before production deployment
  3. Check and install AgentShield before scanning18 of 223 in 12 filesalso worded as check AgentShield is installed before scanning; Verify AgentShield is installed before scanning
  4. Scaffold a secure configuration with init16 of 223 in 10 filesalso worded as Scaffold secure config with init; Scaffold secure configuration with init
  5. Add the AgentShield GitHub Action to CI16 of 223 in 10 filesalso worded as Add the AgentShield action to CI; add the GitHub Action to the CI pipeline
  6. Run the three-agent opus pipeline for deeper analysis14 of 223 in 8 filesalso worded as run the three-agent deep analysis for deeper review; Run the three-agent deep analysis pipeline
  7. Apply safe auto-fixes only14 of 223 in 8 filesalso worded as apply auto-fixes only to auto-fixable findings; Apply only auto-fixable fixes automatically
  8. Use JSON output for CI/CD integration13 of 223 in 7 filesalso worded as use JSON output format for CI integration; Use JSON format for CI integration
  9. Filter findings with a minimum severity12 of 223 in 10 filesalso worded as Filter results by minimum severity; Filter findings to specified severity levels
  10. Classify each finding by severity10 of 223also worded as Classify findings by severity and apply the disposition; Classify findings by severity
  11. Use parameterized queries for all database access10 of 223 in 9 filesalso worded as Use parameterized queries for all SQL; Parameterize every database query
  12. Write tests before writing the rule9 of 223 in 4 filesalso worded as Write test files before writing the rule; Write test cases before writing the rule
  13. Validate all user inputs9 of 223also worded as Verify all user inputs are validated and sanitized; Validate all input server-side
  14. Scan the .claude/ configuration directory8 of 223 in 4 filesalso worded as Scan the project's .claude/ configuration directory; Run the scan against the .claude directory
  15. Set ANTHROPIC_API_KEY before opus analysis8 of 223 in 4 filesalso worded as Export ANTHROPIC_API_KEY before opus analysis; Set ANTHROPIC_API_KEY before deep analysis

What they tell it not to do

  1. Never modify manual-only suggestions20 of 223 in 14 filesalso worded as Never modify manual-only suggestions during auto-fix; Do not modify manual-only suggestions
  2. Never write a rule without tests15 of 223 in 7 filesalso worded as Writing a rule without tests; Never write a rule without tests
  3. Never hardcode secrets15 of 223 in 14 filesalso worded as Never hardcode secrets or real private data; Never hardcode secrets in source
  4. Never concatenate user input into SQL strings14 of 223 in 11 filesalso worded as Never interpolate user input into SQL; Never concatenate user input into queries
  5. Do not skip any workflow steps8 of 223 in 3 filesalso worded as Do not skip any workflow steps; Do not skip workflow steps
  6. Never commit the .env file7 of 223also worded as Never commit .env files, API keys, or credentials; Never commit real .env files to version control
  7. Never expose stack traces in production6 of 223 in 5 filesalso worded as Never expose stack traces in error responses; Never expose stack traces or internal details to users
  8. Never use todook or todoruleid annotations6 of 223 in 2 filesalso worded as Never use todook or todoruleid annotations
  9. Never interpolate user input into raw SQL6 of 223also worded as Never interpolate user input into SQL strings; Never interpolate user input into queries
  10. Do not auto-fix beyond auto-fixable findings5 of 223 in 3 filesalso worded as don't auto-fix findings; Do not auto-fix findings

What they expect to be installed

  1. semgrep51 of 223 in 47 files
  2. npm audit35 of 223 in 34 files
  3. trivy31 of 223 in 29 files
  4. CodeQL25 of 223 in 23 files
  5. gitleaks25 of 223
  6. npm24 of 223 in 17 files
  7. pip-audit22 of 223 in 21 files
  8. git20 of 223 in 18 files
  9. npx ecc-agentshield19 of 223 in 13 files
  10. Snyk15 of 223 in 14 files

What they ask it to produce

  1. HTML security report18 of 223 in 12 filesalso worded as HTML report; security-report.html
  2. Security scan report13 of 223 in 12 filesalso worded as JSON security scan report; Security Scan Results markdown report
  3. Scaffolded settings.json, CLAUDE.md, and mcp.json10 of 223 in 6 filesalso worded as scaffolded settings.json, CLAUDE.md, mcp.json; Scaffolded settings.json
  4. Semgrep rule YAML file9 of 223 in 4 filesalso worded as Ported Semgrep rule YAML; Custom Semgrep rule YAML
  5. JSON report for CI/CD9 of 223 in 5 filesalso worded as JSON audit report for CI; JSON report for CI integration
  6. Test file with ruleid and ok annotations7 of 223 in 3 filesalso worded as Annotated test file with ruleid and ok markers
  7. Scaffolded secure configuration files7 of 223 in 5 filesalso worded as Scaffolded secure config files; Scaffolded secure .claude/ config files
  8. Scan report with severity grade7 of 223 in 3 filesalso worded as colored scan report with severity grade; security scan report grouped by severity

When Vulnerability scanning authors say to reach for one

The situations these authors wrote into their own files, counted out of the same 223 authors, with the skills that name each one

How Vulnerability scanning skills are built

687 skill directories by 197 authors, read from their repositories’ own file trees 2026-08-05

The middle bundle among those shipping files is 3 files, 24.1 KB beside SKILL.md

Counted by distinct author, same as above, so one author publishing forty template copies counts once. SKILL.md itself is not counted as a file, so a single-file skill is one where that file is the whole skill.

The shape

  1. SKILL.md is the whole skill82 of 197 authors, 351 of 687 skills
  2. files ship beside it115 of 197 authors, 336 of 687 skills
  3. executable scripts ship inside50 of 197 authors, 166 of 687 skills

The folders they converge on

  1. references/77 of 197 authors, 240 of 687 skills
  2. scripts/46 of 197 authors, 166 of 687 skills
  3. assets/15 of 197 authors, 76 of 687 skills
  4. evals/9 of 197 authors, 15 of 687 skills
  5. examples/7 of 197 authors, 7 of 687 skills
  6. agents/6 of 197 authors, 9 of 687 skills
  • Secscan skill

    atgreen/secscan-skill Skill

    51

    Mirror of https://cave.moxielogic.com/atgreen/secscan-skill

  • Mythos agent

    mythos-agent/mythos-agent/io.github.mythos-agent/mythos-agent MCP server

    39 repo

    Open-source AI security agent: SAST, DAST, and policy-as-code over MCP.

  • Aegis

    myclaude-sh/myclaude-creator-engine/.claude/skills/aegis Skill

    24 repo

    The creation pipeline for Claude Code products — research, create, validate, publish. 13 types, 20 quality patterns, zero coding required.

  • B3sty skill

    b3sty191/b3sty-skill Skill

    no license8

    b3sty RedM/FiveM Lua Codex skill

  • Snyk API & Web MCP Server

    snyk/saw-mcp/io.github.snyk/saw-mcp MCP server

    7 repo

    MCP server for Snyk API & Web — DAST scanning, findings management, and vulnerability triage

  • Vantage

    tinoimammp/vantage-security-agent/skills/vantage Skill

    4 repo

    AI-powered vulnerability scanner plugin for Claude Code with 28 agents statically scan web & mobile repos for OWASP Top 10 / Mobile Top 10 vulnerabilities, validate findings, and optionally auto-fix them. No live requests, ever.

  • Cybersorted

    cyber-sorted/skills-pro/cybersorted Skill

    no license3 repo

    Professional security and enterprise architecture advisory skills for Claude Code

  • Penkit51 ai

    xAmirHamza77/PenKit51/assistant-skills/chatgpt/penkit51-ai Skill

    no license2 repo

    PenKit51 — Open-source AI penetration testing platform with 63 deep exploitation skills, multi-agent orchestration, PoC-validated findings, and native assistant skills for Claude, ChatGPT, and Grok. Authorized testing only.

  • SAST MCP Server

    Skyrxin/sast-mcp-server/io.github.Skyrxin/sast-mcp-server MCP server

    2 repo

    11-scanner SAST/DAST MCP server with closed-loop remediation, SBOM/SARIF, and CI integrations

  • Anthropic sdk security scan

    Dolphinllc/claude-security-skills/skills/defensive/genai/anthropic-sdk-security-scan Skill

    1 repo

    Defensive security skills for Claude Code and the Claude Agent SDK — web applications and generative AI systems.

  • Aos audit

    riz007/architect-os/skills/aos-audit Skill

    1 repo

    AI-native software engineering operating system for modern application architecture, scaffolding, and AI-assisted development.

  • Sast analysis

    reasonless-throne486/sast-skills/sast-files/.agents/skills/sast-analysis Skill

    0 repo

    Scan codebases for security flaws with LLM agent skills that turn Claude Code, Cursor, and other assistants into SAST scanners

  • Security audit

    ayman-benmada/owasp-security-audit/skills/security-audit Skill

    no license0 repo

    OWASP Top 10 (2025) security audit plugin for Claude Code and Cursor. Stack-aware scanning that produces a complete vulnerability report.

  • Fanout cve iteration loop

    omonuj/claude-horizon-skills/skills/fanout-cve-rollout/fanout-cve-iteration-loop Skill

    no license0 repo

    Claude Code Agent Skills for building, red-teaming and tuning agentic RL evaluation environments — a four-skill pattern (guardian, validation-debugger, score-tuner, iteration-loop) plus a 24-point adversarial reviewer.

  • Bandit

    kpatryk/skills/skills/bandit Skill

    0 repo

    AI skills

  • Trivy security scan

    sokratisg/trivy-security-scan/skills/trivy-security-scan Skill

    0 repo

    Agent-neutral Trivy security scanning skill for local vulnerability, misconfiguration, secret, and license scans.

  • Hermes skill local web security scan

    web3blind/hermes-skill-local-web-security-scan Skill

    no license0

    Local Web Security Scan

  • Codebase security audit

    sjsylee/skills-hub/skills/codebase-security-audit Skill

    0 repo

    바이브 코딩에 규율을 입히는 에이전트 스킬 모음 · Agent skills that bring discipline to vibe coding. Install: npx skills add sjsylee/skills-hub

  • cve-cache

    weiseer/cve-cache-mcp/io.github.weiseer/cve-cache MCP server

    no license0 repo

    Recent CVE + GHSA cache for AI agents auditing dependencies (npm/PyPI/Cargo/Maven/Go).

  • Xss html injection

    tody-agent/codymaster/.agent/skills/xss-html-injection Skill

    no license49 repo

    Vibe Coding Framework - Full SaaS Development Team from A-Z with Brain, Self Improvement, Auto Development

  • Penkit51 ai

    xAmirHamza77/PenKit51/assistant-skills/claude/penkit51-ai Skill

    no license2 repo

    PenKit51 — Open-source AI penetration testing platform with 63 deep exploitation skills, multi-agent orchestration, PoC-validated findings, and native assistant skills for Claude, ChatGPT, and Grok. Authorized testing only.

  • Pwnote cve research

    Pwnote/skills/skills/pwnote-cve-research Skill

    2 repo

    AI agent skills for Pwnote Pentest Notebook

  • Langchain security scan

    Dolphinllc/claude-security-skills/skills/defensive/genai/langchain-security-scan Skill

    1 repo

    Defensive security skills for Claude Code and the Claude Agent SDK — web applications and generative AI systems.

  • Sast businesslogic

    reasonless-throne486/sast-skills/sast-files/.agents/skills/sast-businesslogic Skill

    0 repo

    Scan codebases for security flaws with LLM agent skills that turn Claude Code, Cursor, and other assistants into SAST scanners

  • Fanout cve score tuner

    omonuj/claude-horizon-skills/skills/fanout-cve-rollout/fanout-cve-score-tuner Skill

    no license0 repo

    Claude Code Agent Skills for building, red-teaming and tuning agentic RL evaluation environments — a four-skill pattern (guardian, validation-debugger, score-tuner, iteration-loop) plus a 24-point adversarial reviewer.

  • Sast scan

    jpoindexter/security-skills/sast-scan Skill

    0 repo

    Agent skills for running security scans — secret scanning (gitleaks), dependency CVE audit (npm/cargo/osv), SAST (semgrep), and a composed pre-release gate. Grounded SKILL.md runbooks for Vanta / Claude Code / any skill-aware agent. MIT.

  • Frontend mobile security xss scan

    sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills-claude/skills/frontend-mobile-security-xss-scan Skill

    44,658 repo

    AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.

  • Sast configuration

    sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills-claude/skills/sast-configuration Skill

    44,658 repo

    AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.

  • Security scanning security sast

    sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills-claude/skills/security-scanning-security-sast Skill

    44,658 repo

    AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.

  • Semgrep rule creator

    sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills-claude/skills/semgrep-rule-creator Skill

    44,658 repo

    AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.

  • Semgrep rule variant creator

    sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills-claude/skills/semgrep-rule-variant-creator Skill

    44,658 repo

    AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.

  • Sql injection testing

    sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills-claude/skills/sql-injection-testing Skill

    44,658 repo

    AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.

  • Xss html injection

    sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills-claude/skills/xss-html-injection Skill

    44,658 repo

    AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.

  • Frontend mobile security xss scan

    sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills/skills/frontend-mobile-security-xss-scan Skill

    44,658 repo

    AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.

  • Sast configuration

    sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills/skills/sast-configuration Skill

    44,658 repo

    AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.

  • Security scanning security sast

    sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills/skills/security-scanning-security-sast Skill

    44,658 repo

    AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.

  • Semgrep rule creator

    sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills/skills/semgrep-rule-creator Skill

    44,658 repo

    AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.

  • Semgrep rule variant creator

    sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills/skills/semgrep-rule-variant-creator Skill

    44,658 repo

    AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.

  • Sql injection testing

    sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills/skills/sql-injection-testing Skill

    44,658 repo

    AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.

  • Xss html injection

    sickn33/agentic-awesome-skills/plugins/agentic-awesome-skills/skills/xss-html-injection Skill

    44,658 repo

    AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.

  • Sast configuration

    sickn33/agentic-awesome-skills/plugins/agentic-bundle-aas-secure-app-builder/skills/sast-configuration Skill

    44,658 repo

    AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.

  • Sast configuration

    sickn33/agentic-awesome-skills/plugins/agentic-bundle-aas-security-engineer/skills/sast-configuration Skill

    44,658 repo

    AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.

  • Frontend mobile security xss scan

    sickn33/agentic-awesome-skills/skills/frontend-mobile-security-xss-scan Skill

    44,658 repo

    AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.

  • Sast configuration

    sickn33/agentic-awesome-skills/skills/sast-configuration Skill

    44,658 repo

    AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.

  • Security scanning security sast

    sickn33/agentic-awesome-skills/skills/security-scanning-security-sast Skill

    44,658 repo

    AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.

  • Semgrep rule creator

    sickn33/agentic-awesome-skills/skills/semgrep-rule-creator Skill

    44,658 repo

    AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.

  • Semgrep rule variant creator

    sickn33/agentic-awesome-skills/skills/semgrep-rule-variant-creator Skill

    44,658 repo

    AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.

  • Sql injection testing

    sickn33/agentic-awesome-skills/skills/sql-injection-testing Skill

    44,658 repo

    AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.

  • Xss html injection

    sickn33/agentic-awesome-skills/skills/xss-html-injection Skill

    44,658 repo

    AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 1,987+ agentic skills. Includes CLI, local MCP, catalog, plugins, and Workbench.

  • Sast configuration

    wshobson/agents/plugins/security-scanning/skills/sast-configuration Skill

    38,701 repo

    Multi-harness agentic plugin marketplace for Claude Code, Codex CLI, Cursor, OpenCode, GitHub Copilot, and Gemini CLI

  • Security review

    github/awesome-copilot/skills/security-review Skill

    37,897 repo

    Community-contributed instructions, agents, skills, and configurations to help you make the most of GitHub Copilot.

  • Senior secops

    alirezarezvani/claude-skills/engineering-team/skills/senior-secops Skill

    24,478 repo

    345 Claude Code skills & agent skills & plugins (30+ Agents, 70+ custom commands, 330+ skills, customizable references, scripts)for Claude Code, Codex, Gemini CLI, Cursor, and 8 more coding agents — engineering, marketing, product, compliance, C-level advisory, research, business operations, commercial & finance, and your daily productivity skills.

  • Security guidance

    alirezarezvani/claude-skills/engineering/security-guidance/skills/security-guidance Skill

    24,478 repo

    345 Claude Code skills & agent skills & plugins (30+ Agents, 70+ custom commands, 330+ skills, customizable references, scripts)for Claude Code, Codex, Gemini CLI, Cursor, and 8 more coding agents — engineering, marketing, product, compliance, C-level advisory, research, business operations, commercial & finance, and your daily productivity skills.

  • Skill security auditor

    eigent-ai/eigent/resources/example-skills/skill-security-auditor Skill

    15,013 repo

    Eigent: The Open Source Cowork Desktop - Local and Free Alternative to Claude Cowork and Codex

  • Code reviewer

    Jeffallan/claude-skills/skills/code-reviewer Skill

    10,966 repo

    66 Specialized Skills for Full-Stack Developers. Transform Claude Code into your expert pair programmer.

  • Semgrep rule creator

    trailofbits/skills/plugins/semgrep-rule-creator/skills/semgrep-rule-creator Skill

    6,559 repo

    Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows

  • Semgrep rule variant creator

    trailofbits/skills/plugins/semgrep-rule-variant-creator/skills/semgrep-rule-variant-creator Skill

    6,559 repo

    Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows

  • Semgrep

    trailofbits/skills/plugins/static-analysis/skills/semgrep Skill

    6,559 repo

    Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows

  • Code vuln audit

    zebbern/claude-code-guide/skills/code-vuln-audit Skill

    4,568 repo

    Claude Code Guide - Setup, Commands, workflows, agents, skills & tips-n-tricks go from beginner to power user!

  • Secure code review

    zebbern/claude-code-guide/skills/secure-code-review Skill

    4,568 repo

    Claude Code Guide - Setup, Commands, workflows, agents, skills & tips-n-tricks go from beginner to power user!

All 769 in the catalog